Form pre-fill legal concern
We had a legal concern raised to us by our legal team which I wanted to bring up here to see if anyone in the community has found a workaround or is also struggling with this.
The concern is with the ability to Prefill a form when a Contact visits our web pages and tries to download or access some content. While this is convenient for the users, it also brings up a potential privacy issue for the Contacts. In a nutshell, there are certain data fields, that we maintain for those Contacts in Marketo, that could be exposed to someone else who is using the same email.
Here is the use case:
- 1. Person “A” submit form “1” which has email address, phone number, and other personal information -> lead "A" is created in Marketo.
- 2. Person “B” submit form “2” which only has the minimum fields in Marketo (email), using the email address of person “A”. Now Marketo thinks this person
“B” is person “A” and associates the cookie with lead of person “A”. - 3. Person “B” visit form “1” page, which has pre-fill turned on, revealing person “A”’s personal information that is exposed through the forms.
Even if the pre-filled values are hidden via the functionality in forms 2.0, the source code of the page still exposes this data, and thus poses a potential security threat for person "A".
Obviously form pre-fill is a very powerful feature for increasing conversion rates to content and down the funnel, so any ideas and/or workaround would be great so that we can leverage this key capability without any legal concerns.